Sample viewer

vx.netlux.org/Virus.DOS.Maf.273

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:43.764270684Z 78 PC: 12b0f | Find first file
2018-12-17T23:02:43.770718248Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.77648878Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.779947389Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.783938728Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.788302727Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.791846666Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.795232187Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.799552785Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.802713634Z 44 PC: 12abb | Get time 0x12abb: and dl, bl
0x12abd: xor cx, cx
0x12abf: mov cl, dl
0x12ac1: push cx
0x12ac2: mov dx, 0x1d5
0x12ac5: call 0x12b09
0x12ac8: pop cx
0x12ac9: cmp cl, 0
0x12acc: je 0x12ad3
0x12ace: call 0x12b10
0x12ad1: loop 0x12ace
0x12ad3: mov bx, 0x9a
0x12ad6: mov cx, word ptr [bx]
0x12ad8: cmp cx, 0x111
0x12adc: jb 0x12b08
0x12ade: mov ax, 0x3dc1
0x12ae1: mov dx, 0x9e
0x12ae4: int 0x21
0x12ae6: mov bx, ax
0x12ae8: mov dx, 0x100
2018-12-17T23:02:43.805853603Z 78 PC: 12b0f | Find first file
2018-12-17T23:02:43.813941369Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.817200083Z 71 PC: 12a4c | Get current directory
2018-12-17T23:02:43.820086225Z 25 PC: 12a50 | Get default drive
2018-12-17T23:02:43.821892599Z 14 PC: 12a5b | Set default drive (Drive = 'C')
2018-12-17T23:02:43.823997574Z 25 PC: 12a5f | Get default drive
2018-12-17T23:02:43.825490499Z 78 PC: 12b0f | Find first file
2018-12-17T23:02:43.831519968Z 59 PC: 12a83 | Change current directory
2018-12-17T23:02:43.839006464Z 78 PC: 12b0f | Find first file
2018-12-17T23:02:43.852735519Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.856374396Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.860695636Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.867718541Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.874476218Z 44 PC: 12abb | Get time 0x12abb: and dl, bl
0x12abd: xor cx, cx
0x12abf: mov cl, dl
0x12ac1: push cx
0x12ac2: mov dx, 0x1d5
0x12ac5: call 0x12b09
0x12ac8: pop cx
0x12ac9: cmp cl, 0
0x12acc: je 0x12ad3
0x12ace: call 0x12b10
0x12ad1: loop 0x12ace
0x12ad3: mov bx, 0x9a
0x12ad6: mov cx, word ptr [bx]
0x12ad8: cmp cx, 0x111
0x12adc: jb 0x12b08
0x12ade: mov ax, 0x3dc1
0x12ae1: mov dx, 0x9e
0x12ae4: int 0x21
0x12ae6: mov bx, ax
0x12ae8: mov dx, 0x100
2018-12-17T23:02:43.878323587Z 78 PC: 12b0f | Find first file
2018-12-17T23:02:43.884926824Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.888479799Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.89327059Z 79 PC: 12b14 | Find next file
2018-12-17T23:02:43.897017981Z 61 PC: 12ae6 | Open file (Filename = 'SYS.COM')
2018-12-17T23:02:43.904641395Z 64 PC: 12aef | Write file or device (Write 9432 bytes on handle 5)
2018-12-17T23:02:44.321808745Z 87 PC: 12b04 | Get or set file date and time
2018-12-17T23:02:44.324354899Z 62 PC: 12b08 | Close file
2018-12-17T23:02:44.332369297Z 25 PC: 12a8a | Get default drive
2018-12-17T23:02:44.334802629Z 59 PC: 12a95 | Change current directory
2018-12-17T23:02:44.339978805Z 59 PC: 12a9c | Change current directory
2018-12-17T23:02:44.342509459Z 14 PC: 12aa3 | Set default drive (Drive = 'A')